Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

[CVE-2021-44231] Code Injection vulnerability in SAP ABAP Server & ABAP Platform (Translation Tools), SAP security note 3119365

SAP Note 3119365
SAP Security Note
HotNews

SAP security note 3119365, "Critical Code Injection Vulnerability (CVE-2021-44231)", is a program error note released on 14.12.2021. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > Documentation and Translation Tools > Translation Tools
CategoryProgram error
PriorityHotNews
TypeSAP Security Note
Version9
StatusReleased for Customer
Released on14.12.2021
LanguageEnglish

Description

Symptom

An attacker with low privileges can exploit a weakness in internally used text extraction reports (Translation Tools) to execute arbitrary commands in the background. This allows the attacker to control the behavior of the application, compromising all its data.

Solution

  • Coding is deactivated (commented out).
  • Please apply/implement this note.
  • There is no impact on existing functionality.

Reason and prerequisites

Internally used reports were released by accident.

CVSS

Score 9.9 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected components

  • SAP_BASIS: 701, 740, 750 to 756, 786, 804

Full note on SAP: SAP Support Launchpad note 3119365

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More